First published: Fri May 24 2019(Updated: )
AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language.php and core/lib/language_manager.php, or via POST data to admin/controller/pages/tool/backup.php and admin/model/tool/backup.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Abantecart | =1.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10755 has been classified with a high severity level due to its potential for SQL Injection attacks.
To address CVE-2016-10755, update AbanteCart to a version later than 1.2.8 that contains patches for these vulnerabilities.
CVE-2016-10755 affects the source_language parameter in specific files within AbanteCart 1.2.8.
CVE-2016-10755 can allow attackers to execute arbitrary SQL queries, potentially leading to unauthorized data access or manipulation.
CVE-2016-10755 is not a remote code execution vulnerability, but it could lead to data breaches and further exploitation if not mitigated.